23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 6201-6250 of 23295 CVEs Page 125 of 466
CVE-2026-46562
Analyzed
9.8
Yamcs Yamcs

A code injection vulnerability in the Yamcs mission control framework allows unauthenticated attackers to execute arbitrary OS commands via the Nashor...

2026-07-17
CVE-2026-46558
Analyzed
8.3
Intel Plane

Plane is an open-source project management tool

2026-06-12
CVE-2026-46519
Analyzed
8.8
Kubernetes mcp-server-kubernetes

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management

2026-06-12
CVE-2026-46515
Analyzed
9.3
Unknown frogman

A missing authorization vulnerability in mwtcmi frogman allows authenticated users with low-level permissions to access sensitive system secrets and e...

2026-07-17
CVE-2026-46512
Analyzed
9.9
Unknown Frogman

An input validation flaw in the Frogman PBX control software allows authenticated users with writing privileges to inject arbitrary Asterisk directive...

2026-07-17
CVE-2026-46491
Analyzed
8.6
HP casserver

SimpleSAMLphp-casserver is a CAS 1

2026-06-11
CVE-2026-46490
Analyzed
8.8
Samlify Samlify

samlify is a Node

2026-06-10
CVE-2026-46489
Analyzed
8.1
SolidInvoice SolidInvoice

SolidInvoice is an open-source invoicing platform

2026-06-13
CVE-2026-46485
Analyzed
8.2
Lissy93 Dashy

Dashy is a self-hostable personal dashboard

2026-07-17
CVE-2026-46484
Analyzed
8.1
Headplane Headplane Web UI

Headplane is a feature-complete Web UI for Headscale

2026-06-09
CVE-2026-46481
Analyzed
8.3
Intel OpenMetadata Platform

OpenMetadata is a unified metadata platform

2026-06-09
CVE-2026-46480
Analyzed
8.8
FlowiseAI Flowise

Flowise is a drag & drop user interface to build a customized large language model flow

2026-06-10
CVE-2026-46479
Analyzed
8.8
Flowise Flowise

Flowise is a drag & drop user interface to build a customized large language model flow

2026-06-16
CVE-2026-46478
Analyzed
8.8
Flowise Flowise

Flowise is a drag & drop user interface to build a customized large language model flow

2026-06-16
CVE-2026-46477
Analyzed
8.8
Flowise Flowise

Flowise is a drag & drop user interface to build a customized large language model flow

2026-06-16
CVE-2026-46476
Analyzed
8.8
Intel Flowise

Flowise is a drag & drop user interface to build a customized large language model flow

2026-06-16
CVE-2026-46475
Analyzed
8.8
Flowise Flowise

Flowise is a drag & drop user interface to build a customized large language model flow

2026-06-13
CVE-2026-46473
Analyzed
7.5
Unknown Multiple Products

Authen::TOTP versions before 0

2026-05-22
CVE-2026-46457
Analyzed
7.5
Apache Apache Camel

Improper Input Validation vulnerability in Apache Camel NATS component

2026-07-07
CVE-2026-46456
Analyzed
9.8
Apache Camel

Improper input validation in the Apache Camel AWS2-SQS component allows attackers to inject arbitrary control headers, potentially hijacking downstrea...

2026-07-07
CVE-2026-46455
Analyzed
9.8
Apache Apache Camel

The Apache Camel Keycloak component fails to properly validate token expiration and 'not-before' claims, allowing the acceptance of expired or invalid...

2026-07-07
CVE-2026-46454
Analyzed
9.8
Apache Apache Camel

The Apache Camel Cometd component is vulnerable to improper input validation, allowing unauthenticated remote attackers to inject control headers and...

2026-07-07
CVE-2026-4645
Analyzed
7.5
GitHub Multiple Products

A flaw was found in the `github

2026-03-24
CVE-2026-46444
Analyzed
8.8
Intel Flowise

Flowise is a drag & drop user interface to build a customized large language model flow

2026-06-11
CVE-2026-46439
Analyzed
7.8
Unknown compliance-trestle

compliance-trestle is a tooling platform for managing compliance as code

2026-08-16
CVE-2026-46425
Analyzed
9.9
Budibase Budibase

Budibase contains an authorization bypass vulnerability in the SCIM API, allowing authenticated users to perform unauthorized CRUD operations on all u...

2026-05-28
CVE-2026-46423
Analyzed
9.3
RocketChat Rocket.Chat

Rocket.Chat's SAML implementation fails to validate signatures when no IdP certificate is configured, allowing unauthenticated attackers to bypass aut...

2026-06-25
CVE-2026-46417
Analyzed
8.8
Google Angular

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

2026-06-23
CVE-2026-46415
Analyzed
8.2
JasonLovesDoggo caddy-defender

The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address

2026-07-21
CVE-2026-46414
Analyzed
8.8
Microsoft UFO open

Microsoft UFO open-source framework for intelligent automation across devices and platforms

2026-05-28
CVE-2026-46412
Analyzed
10
GitHub beproduct-org-nestjs-auth

The @beproduct/nestjs-auth package was compromised via a malicious npm publish, leading to the distribution of versions containing code designed to ex...

2026-07-21
CVE-2026-46410
Analyzed
8.7
Unknown filebrowser

FileBrowser Quantum is a free, self-hosted, web-based file manager

2026-07-21
CVE-2026-46408
Analyzed
7.6
Unknown Multiple Products

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

2026-05-17
CVE-2026-46407
Analyzed
8.1
Unknown Multiple Products

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

2026-05-16
CVE-2026-4640
Analyzed
7.5
Samsung Multiple Products

Vitals ESP developed by Galaxy Software Services has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to execute cert...

2026-03-24
CVE-2026-4639
Analyzed
8.8
Samsung Multiple Products

Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticated remote attackers to perform certa...

2026-03-24
CVE-2026-46389
Analyzed
10
Kubernetes UDS Identity Config

A logic error in the Kubernetes UDS Identity Config component allows attackers to bypass client secret authentication and obtain unauthorized OAuth2 t...

2026-06-06
CVE-2026-46386
Analyzed
9.9
Docker OpenProject

A default, insecure secret key configuration in the official OpenProject Docker image allows authenticated users to achieve remote code execution via...

2026-06-27
CVE-2026-46382
Analyzed
8.7
HP mrbs-code

The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms

2026-08-13
CVE-2026-46368
Analyzed
8.8
OpenWrt luci-app-https-dns-proxy

luci-app-https-dns-proxy through 2025

2026-05-27
CVE-2026-46367
Analyzed
7.6
HP Multiple Products

phpMyFAQ before 4

2026-05-16
CVE-2026-46366
Analyzed
7.5
HP Multiple Products

phpMyFAQ before 4

2026-05-17
CVE-2026-46364
Analyzed
9.8
HP phpMyFAQ

phpMyFAQ contains an unauthenticated SQL injection vulnerability in its captcha handling methods, allowing attackers to extract sensitive database inf...

2026-05-16
CVE-2026-4636
Analyzed
8.1
Infor Multiple Products

A flaw was found in Keycloak

2026-04-03
CVE-2026-46359
Analyzed
7.5
HP Multiple Products

phpMyFAQ before 4

2026-05-17
CVE-2026-46354
Analyzed
9.1
Microsoft Coder

Coder contains an improper cryptographic signature verification flaw in `azureidentity.Validate()`, allowing attackers to forge session tokens via man...

2026-07-08
CVE-2026-46353
Analyzed
8.1
Unknown bigbluebutton

BigBlueButton is an open-source virtual classroom

2026-07-17
CVE-2026-46351
Analyzed
8.1
Unknown bigbluebutton

BigBlueButton is an open-source virtual classroom

2026-07-17
CVE-2026-46348
Analyzed
8.7
Mastodon Mastodon

Mastodon is a free, open-source social network server based on ActivityPub

2026-06-25
CVE-2026-46345
Analyzed
8.4
Unknown compliance-trestle

compliance-trestle is a tooling platform for managing compliance as code

2026-08-18